CVE Tools

Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

Ars Technica (Security)By Dan Goodin

ResearchWindowsUEFI

Our summary

Researchers at ESET have uncovered a critical flaw in Microsoft’s Secure Boot implementation, which has been vulnerable to bypass for over a decade due to unrevoked firmware 'shims' signed by the company. These shims, originally designed to support Linux and utility software, remain trusted despite known vulnerabilities and can be exploited to install malicious firmware on both Windows and Linux devices. The issue affects UEFI-based systems and highlights weaknesses in how Secure Boot is managed. Microsoft addressed the problem in its June 2026 update, but users are advised to verify their revocation status using tools like uefi-dbx-audit.

Read at Ars Technica (Security)

Ars Technica (Security) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store